post by admin 2012-5-17 11:04 Thursday
post by admin 2012-5-3 8:37 Thursday
过程简单说下,记的有点乱不贴太多代码了
if(!defined(''IN_DISCUZ'')) {
@@ -89,7 +89,7 @@
}
}
if($searcharray && $replacearray) {
- $content = preg_replace("/(<a\s+.*?>.*?<\/a>)|(<img\s+.*?[\/]?>)|
(\[attach\](\d+)\[\/attach\])/ies", ''helper_seo::base64_transform
("encode", "<relatedlink>", "\\1\\2\\3", "</relatedlink>")'', $content);
+ $content = preg_replace("/(<a\s+.*?>.*?<\/a>)|(<img\s+.*?[\/]?>)|
标签: Discuz!X2.5 EXP
post by admin 2012-5-3 8:36 Thursday
问题位置:huangou.php ID过滤不严格
$id =$_GET[''id''];
$good=sel_sql(‘dhlist’,''id,name,pic,money,jifen,num,content,num’,''id=’.$id);
详细说明:
7.4 3月20号之前的代码,注入确实没修,huangou.php
$id =$_GET[''id''];
$good=sel_sql(‘dhlist’,''id,name,pic,money,jifen,num,content,num’,''id=’.$id);
post by admin 2012-5-3 8:34 Thursday
post by admin 2012-2-14 8:18 Tuesday
post by admin 2012-2-14 8:14 Tuesday
post by admin 2012-2-14 8:00 Tuesday
post by admin 2012-1-19 15:05 Thursday
标题: Joomla Discussions Component (com_discussions) SQL Injection Vulnerability
作者: Red Security TEAM bbs.3344.eu
下载地址: http://extensions.joomla.org/extensions/communication/forum/13560
测试平台: CentOS
测试示例:
# http://www.0517net.com/index.php?option=com_discussions&view=thread&catid=[SQLi]
#
作者: Red Security TEAM bbs.3344.eu
下载地址: http://extensions.joomla.org/extensions/communication/forum/13560
测试平台: CentOS
测试示例:
# http://www.0517net.com/index.php?option=com_discussions&view=thread&catid=[SQLi]
#
标签: Joomla
post by admin 2012-1-18 8:55 Wednesday
post by admin 2012-1-18 8:54 Wednesday
Apusic Web管理控制台
默认后台地址:admin/login.jsp
默认管理账号密码:admin admin
利用方法:后台有执行SQL语句的地,也有加载神马的。具体字样忘记了~
找到上传的地,一个加载神马的,只要看到“浏览”二字,你就懂了。建立一个完了命名t00ls,然后将一个war后缀的JSP马上传。
默认后台地址:admin/login.jsp
默认管理账号密码:admin admin
利用方法:后台有执行SQL语句的地,也有加载神马的。具体字样忘记了~
找到上传的地,一个加载神马的,只要看到“浏览”二字,你就懂了。建立一个完了命名t00ls,然后将一个war后缀的JSP马上传。
标签: 金蝶Apusic Web


